Cookie Governance & Consent Transparency
Effective Date: October 07, 2026 | Version: 3.0
Privacy-First Commitment: FreeURLShort respects your browsing privacy. We do not use intrusive cross-site tracking cookies. This Cookie Policy explains clearly what cookies and local storage items we set, why we use them, and how you retain full control over your preferences.
1. What Are Cookies and Local Storage?
This Cookie Policy explains how the FreeURLShort free URL shortener utilizes cookies and browser local storage when you access our link creation tools and user dashboards.
A cookie is a small text file containing a string of alphanumeric characters that a website places on your computer, smartphone, or tablet when you visit. Cookies enable web servers to remember your actions, login sessions, and display preferences across browsing sessions.
In addition to cookies, we may use related modern web storage technologies such as localStorage and sessionStorage. These operate similarly to cookies but store data directly inside your browser without transmitting data on every HTTP request header.
2. How FreeURLShort Uses Cookies
We use cookies and web storage exclusively for legitimate, transparent operational purposes:
- Session Maintenance & Security: To keep you securely logged into your Customer Dashboard or Admin Portal and protect forms against Cross-Site Request Forgery (CSRF).
- Functional Preferences: Remembering your chosen UI theme (e.g., Light Mode vs. Dark Mode) and dismissed interface notices.
- Performance & Telemetry: Aggregated measurement of website speed, error rates, and feature usage to optimize our engineering stack.
- Bot & Spam Shielding: Ensuring automated bot attacks and credential stuffing scripts are identified before accessing public shortening forms.
3. Comprehensive Categorized Cookie Inventory
Below is a transparent, itemized schedule of all cookies utilized across freeurlshort.com:
A. Strictly Necessary Cookies (Essential)
These cookies are strictly required for our web application to function. Because the site cannot operate without them, they do not require prior consent under EU ePrivacy Directive regulations.
| Cookie Name | Provider | Purpose & Data Stored | Lifespan | Type |
|---|---|---|---|---|
freeurlshort_session |
First-Party (FreeURLShort) | Stores an encrypted session token identifying your active authenticated user session across page requests. | 2 Hours / Session | HTTP, Secure, HttpOnly |
XSRF-TOKEN |
First-Party (FreeURLShort) | Cryptographic security token used to protect forms against Cross-Site Request Forgery (CSRF) exploits. | 2 Hours / Session | HTTP, Secure, SameSite=Lax |
cf_clearance |
Cloudflare (Edge CDN) | Stores proof that a client successfully passed a Cloudflare security challenge, preventing repetitive bot verification. | 1 Year | HTTP, Secure, HttpOnly |
cf_bm |
Cloudflare (Edge CDN) | Used by Cloudflare Bot Management to identify and mitigate automated malicious traffic in real time. | 30 Minutes | HTTP, Secure, HttpOnly |
B. Functional & Preference Cookies
These cookies enable enhanced platform personalization and persist your user preferences across visits.
| Cookie / Storage Key | Provider | Purpose & Data Stored | Lifespan | Type |
|---|---|---|---|---|
theme_preference |
First-Party (FreeURLShort) | Stores your chosen visual interface mode (light or dark) to prevent visual flash on page reload. |
1 Year | localStorage |
cookie_consent_status |
First-Party (FreeURLShort) | Remembers your cookie banner consent decisions so the banner does not reappear repeatedly. | 6 Months | localStorage |
C. Analytics & Performance Cookies
These cookies help us understand how visitors interact with our educational guides, documentation, and feature pages by collecting aggregated, non-personally identifiable telemetry.
| Cookie Name | Provider | Purpose & Data Stored | Lifespan | Type |
|---|---|---|---|---|
_ga |
Google Analytics (GA4) | Assigns a randomly generated client identifier to calculate visitor, session, and campaign data for site analytics reports. | 2 Years | HTTP, Secure |
_ga_* |
Google Analytics (GA4) | Used by Google Analytics 4 to persist session state across browsing paths on our website. | 24 Hours | HTTP, Secure |
4. Do Shortened Links Drop Cookies on Redirected Visitors?
Clear Transparency on Link Redirects:
When a consumer clicks on a shortened link created through FreeURLShort (e.g.,freeurlshort.com/xyz123or a customer's branded custom domain), our server performs an instantaneous, clean HTTP 301 Permanent or HTTP 307/308 Temporary redirect directly to the destination website.
FreeURLShort DOES NOT inject tracking cookies, advertising pixels, or persistent identifier cookies into the redirected visitor's browser during this redirection process. Any cookies subsequently set on the visitor's device are solely governed by the destination website to which the visitor navigates.
5. How to Manage and Disable Cookies
For detailed instructions on controlling cookies across different web browsers, visit All About Cookies and consult the European Data Protection Board (EDPB) cookie guidelines. For overall privacy rules, review our Privacy Policy and GDPR Rights Statement.
You have the absolute right to accept, reject, or customize cookies at any time. Most modern browsers automatically accept cookies by default, but you can modify your browser settings to decline cookies or alert you when a cookie is placed:
- Google Chrome: Settings → Privacy and security → Third-party cookies → Choose your preferred blocking level.
- Mozilla Firefox: Settings → Privacy & Security → Enhanced Tracking Protection → Choose Standard or Strict.
- Apple Safari: Settings → Safari → Advanced → Block All Cookies.
- Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies and site data.
Please note that disabling strictly necessary cookies (such as freeurlshort_session and XSRF-TOKEN) will prevent you from signing in to your Customer Dashboard or generating authenticated short links.
6. Global Privacy Control (GPC) & Do Not Track (DNT)
FreeURLShort actively honors the Global Privacy Control (GPC) browser signal. If your browser broadcasts an active GPC header, our platform automatically disables non-essential analytics tracking for your session. While internet standards regarding legacy "Do Not Track" (DNT) signals remain unstandardized across industry bodies, we treat DNT signals with equivalent respect by restricting optional telemetry.
7. Updates to This Cookie Policy
We may update this Cookie Policy periodically to reflect technological enhancements, new vendor integrations, or regulatory updates. Any changes will be posted here with an updated "Effective Date".
8. Contact Us
If you have any questions or require clarification regarding our use of cookies and tracking technologies, please contact our Data Protection Team at privacy@freeurlshort.com.